MAC Layer Integrity Protection for 5G Control Data Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Next-generation mobile communication systems face security vulnerabilities due to the lack of cooperative security measures between base stations and user equipment, leading to potential protocol malfunctions, errors, and performance degradation, particularly in the handling of PDCP control data, RLC headers, RLC control data, MAC subheaders, and MAC control information.

Innovation Solution

Implementing a method where the MAC layer performs integrity protection and ciphering procedures on MAC PDUs, including PDCP control data, RLC control data, and MAC control information, to enhance security by applying a data protection procedure or data protection release procedure, thereby preventing malicious attacks and ensuring secure data transmission.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If integrity protection and ciphering procedures are applied at the MAC layer to protect control data, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the data protection mechanism by introducing a specific indicator field within the MAC PDU structure to mark integrity-protected subPDUs. This segmentation allows the receiver to identify and verify protected data without requiring complex overall processing, thus improving security while managing device complexity through structured data organization.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies preliminary action by performing integrity protection and ciphering procedures at the MAC layer before data transmission. The transmitting apparatus pre-processes control data with integrity protection indicators, so that the receiving apparatus can efficiently verify security without performing complex real-time analysis, thereby enhancing security while controlling processing complexity.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If integrity protection procedures are applied to MAC subPDUs, then reliability is improved, but processing time increases

Engineering Contradiction:
ImprovereliabilityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The transmitting apparatus performs integrity protection procedures in advance during data preparation, embedding verification indicators into the MAC PDU structure before transmission. This preliminary action allows the receiving apparatus to perform faster verification by checking pre-computed indicators rather than performing complex integrity checks on the entire data stream, thus improving reliability while reducing processing time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces complex mechanical integrity verification processes with cryptographic hash-based integrity protection indicators. Instead of performing exhaustive validation of control data elements, the system uses efficient cryptographic verification through the indicator field, substituting a computationally intensive mechanical verification process with a faster cryptographic check that maintains high reliability.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If data protection procedures are applied to control information, then security is improved, but ease of operation deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments control information into protected and unprotected portions using the indicator field in the MAC PDU structure. This segmentation allows the receiving apparatus to selectively apply data protection procedures only to marked subPDUs, maintaining security for critical control information while simplifying processing of non-critical data, thus improving security while preserving ease of operation through selective protection.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The MAC PDU structure includes self-identifying indicator fields that automatically mark which subPDUs require integrity protection. This self-service mechanism allows the receiving apparatus to automatically identify and process protected data without requiring complex external control or manual configuration, thereby improving security through automated protection while maintaining ease of operation through self-identifying data structures.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12192766B2Method and apparatus for enhancing security of MAC layer entity in next-generation mobile communication system
Publication Date: 2025.01.07 SAMSUNG ELECTRONICS CO LTD
  • US12192766B2 patent drawing
  • US12192766B2 patent drawing
  • US12192766B2 patent drawing

AI summary

The disclosure relates to a 5G or 6G communication system for supporting a higher data transmission rate. It is possible to provide methods for enhancing security when a UE and a base station perform data communication in a next-generation mobile communication system according to an embodiment of the disclosure.